{
 "jurisdiction_id": "IN",
 "jurisdiction": "India",
 "url": "https://dataprotection.gi/jurisdictions/india/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 34,
  "sub_modules": 57,
  "source_register": 20
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/india/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Regulator now exists and rules are finalized (not draft), but the material scope, territorial scope and registration provisions are enacted-but-not-yet-effective pending the 13 May 2027 commencement date.",
   "claims": [
    {
     "statement": "The Data Protection Board of India's establishment and operational/powers provisions were brought into force immediately upon the 13 November 2025 notification of the DPDP Rules, 2025.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/with-rules-finalized-india-s-dpdpa-takes-force",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPDPA becomes applicable to all entities and government departments 18 months after the 13 November 2025 Rules notification, i.e., 13 May 2027.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-india-releases-dpdpa-rules-ai-governance-guidelines",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DPDPA applies to the processing of digital personal data within India, excluding non-digitized offline data, personal data processed for domestic use, and data made publicly available.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/DG-india-dpdpa-infographic.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DPDPA also applies to processing outside India if the processing relates to activity connected with offering goods or services to data principals within India.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/DG-india-dpdpa-infographic.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Rules on the registration and functioning of consent managers apply 12 months after the finalization of the DPDP Rules (from 13 Nov 2025).",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/with-rules-finalized-india-s-dpdpa-takes-force",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/india/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Lawful-basis and consent architecture is well documented; special-category and pseudonymisation treatment diverges structurally from GDPR and required an explicit absence finding for pseudonymisation.",
   "claims": [
    {
     "statement": "DPDPA prescribes nine additional grounds for processing personal data beyond consent, defined as 'legitimate uses,' including use of voluntarily provided data for a specified purpose where the data principal has not objected.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa-part6",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPDPA's consent-centric framework requires that consent obtained from data principals be free, specific, informed, unconditional, and unambiguous.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/with-rules-finalized-india-s-dpdpa-takes-force",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPDPA treats all personal data uniformly without imposing heightened obligations for sensitive personal data, diverging from the GDPR's special-category regime.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa-part6",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/india/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core rights are documented via secondary legal analysis, but portability, restriction/objection, and precise deadline mechanics require primary Rule-text confirmation.",
   "claims": [
    {
     "statement": "DPDPA codifies data principal rights including access, correction, erasure, grievance redressal, and the right to nominate another person to exercise rights on the data principal's behalf.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Unlike the GDPR and CCPA, the rights available to data principals under the DPDPA are limited to access, correction, completion, and nomination, with no explicit portability or general objection/restriction right.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa-part6",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/india/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Strong secondary-source coverage of DPIA/DPO/breach/retention duties, but exact SDF designation thresholds and breach-notification timelines await primary Rule-text confirmation.",
   "claims": [
    {
     "statement": "Only entities classified as Significant Data Fiduciaries are required to conduct a DPIA, and must do so every 12 months.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa-part9",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPDPA requires all Significant Data Fiduciaries to appoint a DPO based out of India, who must represent the significant data fiduciary and be accountable to its board of directors or governing body.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa-part6",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPDPA does not require data fiduciaries to maintain a formal record of processing activities, unlike GDPR Art 30.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa-part6",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In the DPDPA, regulation of data processors is minimal, with only a handful of provisions on the topic, with the law focused almost entirely on data fiduciaries.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa-part3",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data fiduciaries are required to protect personal data under their control or possession and implement necessary security safeguards to prevent a personal data breach.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa-part6",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The finalized DPDP Rules, 2025 cover data breach notification requirements to the Data Protection Board of India and affected data principals.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/with-rules-finalized-india-s-dpdpa-takes-force",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The final DPDP Rules impose a new one-year minimum retention requirement on data fiduciaries, primarily to facilitate responses to state agency requests related to national security, investigations, and determination of significant data fiduciary status.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/dawn-of-india-s-new-privacy-era",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/india/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "The blacklist mechanism is well documented, but no country has yet been notified as restricted, and sector-specific localisation interacts with, rather than is superseded by, the DPDPA.",
   "claims": [
    {
     "statement": "The DPDPA adopts a liberalized 'blacklisting' model under which the central government can notify specific countries to which data flow may be restricted, in contrast to the EU's 'whitelisting' adequacy approach.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/why-de-localizing-data-helps-india-s-position",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPDPA generally allows international data transfers except where the government restricts transfers to specific countries, departing from an adequacy-based transfer method entirely.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa-part6",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Sector-specific guidance from regulators such as the RBI and SEBI, mandating financial datasets to be stored in India, operates alongside the DPDPA's baseline transfer rule.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/dcsi_privacy_across_borders-_guidance_on_cross-border_data_transfers_for_indian_organizations.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/india/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial-sector overlay is well evidenced; other sectoral sub-modules require targeted follow-up research against sector regulator (RBI, IRDAI, TRAI, UGC/health-ministry) primary sources.",
   "claims": [
    {
     "statement": "Sector-specific guidance released by regulators such as the RBI and SEBI, mandating financial datasets to be stored in India, operates alongside the DPDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/dcsi_privacy_across_borders-_guidance_on_cross-border_data_transfers_for_indian_organizations.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/india/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Only the children-targeted-advertising ban was substantiated; broader adtech sub-modules are largely unaddressed by the DPDPA and require dedicated follow-up.",
   "claims": [
    {
     "statement": "Data fiduciaries are prohibited from undertaking processing that involves tracking, behavioral monitoring of children, or targeted advertising directed at children, subject to narrow prescribed exemptions.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa-part6",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/india/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Profiling restriction and state-exemption findings are sourced; ADM transparency, AI risk assessment, biometric and genetic sub-modules remain unaddressed by DPDPA and require dedicated follow-up (and cross-reference to the AI-governance surface).",
   "claims": [
    {
     "statement": "Data fiduciaries are prohibited from undertaking processing that involves tracking or behavioral monitoring of children, except when providing certain essential services such as health care, education, or real-time safety.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa-part6",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Provisions granting exemptions to the government and government bodies under the DPDPA have been described by Justice B.N. Srikrishna, former chair of the Expert Committee on Data Protection, as causing 'great concern.'",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "MeitY released the India Artificial Intelligence Governance Guidelines on 5 November 2025, a separate non-DPDPA instrument relevant to algorithmic governance context.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-india-releases-dpdpa-rules-ai-governance-guidelines",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/india/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Core child/dependent-adult consent architecture is well sourced from the finalized Rules; education-settings sub-module remains unaddressed.",
   "claims": [
    {
     "statement": "The DPDPA defines a child as an individual under age 18 for purposes of the parental/guardian consent requirement.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa-part6",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Verifiable consent must be obtained from the parent or lawful guardian before processing a child's personal data; the finalized Rules elaborate mechanisms such as digital-locker-based parental verification, with narrowly defined health- and safety-specific exemptions.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/with-rules-finalized-india-s-dpdpa-takes-force",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data fiduciaries are prohibited from processing that involves tracking, behavioral monitoring, or targeted advertising directed at children, though the government may notify exempt classes of fiduciaries.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa-part6",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "For individuals with disabilities, consent must be obtained from their lawful guardian, who must be verified in accordance with India's guardianship laws.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa-part6",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/india/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Penalty framework and Board constitution are well documented; enforcement-activity track record under DPDPA itself is not yet available since substantive obligations are not yet effective, and collective-redress mechanisms remain unconfirmed.",
   "claims": [
    {
     "statement": "Sanctions under DPDPA are monetary penalties which, unlike GDPR's turnover-based penalties, may extend to INR 250 crores (approximately USD27 million); the DPDPA imposes no criminal penalties and does not consider business turnover in determining the penalty.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/resources/article/operational-impacts-of-indias-dpdpa-part6",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPDPA provides no statutory right to claim damages, though the new rules indicate a mediation mechanism carried out by the DPBI that may serve as an indirect way for data fiduciaries to settle disputes with data principals.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/with-rules-finalized-india-s-dpdpa-takes-force",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Rules for the establishment of the four-person Data Protection Board of India took force with their publication in the Official Gazette on 13 November 2025.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/with-rules-finalized-india-s-dpdpa-takes-force",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DPIAs are mandated only for Significant Data Fiduciaries under the DPDPA and DPDP Rules, required when processing is likely to result in high risk to individuals' rights, and must be conducted once every 12 months, per Sections 8 and 10 of the DPDPA and Rule 13 of the DPDP Rules.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/article/guidance_note-652763",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "India's Competition Commission (CCI) fined Meta and WhatsApp approximately Rs 213 crore (~USD24 million) in a November 2024 order over a 2021 WhatsApp privacy-policy data-sharing update, a penalty upheld on appeal though a related data-sharing ban was reversed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-india-releases-dpdpa-rules-ai-governance-guidelines",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}